Live data from Hacker News

FastMail’s servers are in the US – what this means for you

blog.fastmail.fm

41–50 of 175 posts

Re: FastMail’s servers are in the US – what this means for you

#41

Earlier quoted context omitted.

Because most of our customers are in the US. If your goal is to provide the fastest service around, it helps to put your servers near your users.

You're implying that you would make less money by trading in your US location for more security. That means that you believe not enough users care enough about their privacy to accept that (really light) trade-off.

It might also mean that many of our users believe in the same tradeoff that we do - that we're not overreacting to one low probability/high visibility risk by throwing out the incredibly good reliability we've had for years to shut everything down, ship it to a location with unknown reliability and spin it all back up again - complete with new IP addresses and all the headache that would cause tons of customers who have hard coded things on their own domains (annoying but true - recycling IPs is hard)

There are tons of downsides to shutting down everything that's working well in a knee-jerk reaction to one possible risk - never mind that the government of whatever country we choose could very well cooperate with the same agencies we're running from - or they could just corrupt an employee of the datacentre we're in - or...

So maybe if you're going to put words into our mouth you could put ones about how much we care about our users and our reliability that we don't jump on unproven setups just because of a single (unchanged, just more public) risk.

Re: FastMail’s servers are in the US – what this means for you

#42
post #35

Earlier quoted context omitted.

"This kind of frank disclosure should be highly rewarded." Yep, definitely. I think even more important than the information itself is the spirit of honesty and integrity that it demonstrates. This stands in stark contrast to the ambiguous slimeball statements issued by the likes of Google, Facebook, Apple, Microsoft, etc. When Big Brother comes knocking, which companies are going to take a risk to stand up for you?…

Note that G, FB, A and MS are not in a position where they can write such disclosure. I am not arguing with your main point, I applaud FastMail for taking a stand - it's just that USA companies must use "ambiguous slimeball statements" to at least appear clean (because they are not). I would argue that if FastMail were an USA company their statements (if any) would be just as ambiguous as those of G, FB, A and MS.

I understand your viewpoint, but I don't accept that as an excuse.

Remember how quickly SOPA sank after the Silicon Valley establishment turned against it? Do you think the government is going to put the CEOs of some of America's most popular and profitable companies in jail for an act of civil disobedience that the majority of the country and the world would support wholeheartedly?

SV is more powerful than it realizes, and has little to fear in the current climate. The American national security state, on the other hand, is weakened and vulnerable. Now is the time to take a stand. Not doing so is equivalent to complicity.

Re: FastMail’s servers are in the US – what this means for you

#43

Earlier quoted context omitted.

If they mount webcams and other sensors inside the cabinet, they could detect unexplained access to their servers. Not sure what it'd really accomplish. The colo provider would either say "tech mistakenly opened that cabinet" or "no comment". The only real defense is to assume any such access is a breach and have servers immediately overwrite FDE keys in RAM and power off - and if they were that committed, they would…

There is some historical precedent for such methods. I believe one popular CDN (possibly Akamai?) has its nodes set up with sensors of some variety to discard sensitive data if the hardware is exposed to light.

Dell (and possibly others) servers have chassis intrusion sensors that you can trap in software, and do with as you please.

Re: FastMail’s servers are in the US – what this means for you

#44

The US government will just take their server. They don't care if you go out of business. Look at what they did to megaupload.com.

There's a difference between going after a company that is obviously facilitating copyright infringement and is mainly used for that purpose vs. going after a respectable service provider. The latter would raise hell in the international relations between countries.

Re: FastMail’s servers are in the US – what this means for you

#45

> our primary servers are located in the US Why would you do that, especially when you're not even a US company?

Because most of our customers are in the US. If your goal is to provide the fastest service around, it helps to put your servers near your users.

But maybe most of your users are from the US because the servers are there? I'm from Europe and was a FastMail customer once, but I switched away because I didn't trust the US-based servers (and that was even before the NSA scandal).

Re: FastMail’s servers are in the US – what this means for you

#47

> Australia does not have any equivalent to the US National Security Letter, so we cannot be forced to do something without being allowed to disclose it. This is not true. The Australian Crime Commission has some of the most extensive secret coercive powers in the Western world. http://www.austlii.edu.au/au/legis/cth/consol_act/acca200228... I would suggest that either: a) Fastmail is aware of this and is covertly sp…

I would argue that section 29 is very narrow in its scope, and allows for disclosure once an investigation is completed, and allows for disclosure to an attorney, whereas my understanding of an NSL is that it can order pretty much anything it wants without limitation. That seems quite different to me.

But then, I'm not lawyer. You're probably not either. Which is why I keep telling people to get their own legal advice if they're concerned about it.

Re: FastMail’s servers are in the US – what this means for you

#48
I found this article brutally honest. What they are saying is that (1) NSA snooping is more expensive for the NSA as they can't engage in blanket surveillance on all of their users, while keeping them silent, but on the other hand (2) you can't expect and shouldn't assume privacy, because if the NSA wants to listen on your traffic, they will.

This in combination with FastMail being acquired by its former employees, coupled with their investment in CardDAV and CalDAV, makes me really excited about them. I was actually looking for a good replacement to Google Apps and FastMail might be it. It's still a little expensive though, compared to Google Apps, I hope they'll bring those prices down just a little.

Re: FastMail’s servers are in the US – what this means for you

#49

I found this article brutally honest. What they are saying is that (1) NSA snooping is more expensive for the NSA as they can't engage in blanket surveillance on all of their users, while keeping them silent, but on the other hand (2) you can't expect and shouldn't assume privacy, because if the NSA wants to listen on your traffic, they will. This in combination with FastMail being acquired by its former employees, c…

I think there's reason to believe that a targeting a person like Snowden would cause the U.S. to use the most extreme measures discussed in the post, such as seizing the servers.
Post reply on HN